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Top Priority Projects Underway at A2SC 


Project prioritization criteria: Support Immigration levels, increase efficiencies, and/or enhance program integrity. 
With current resources, AA team can undertake between 5 and 7 projects concurrently. 
The estimated delivery dates hinge on many dependencies, including: 

e Availability of experts within Ops to adapt business processes and ensure governance. 


e IT support 
e Addressing applicable Legal, Privacy, Policy and Governance considerations 


Automate the manual triage using 
AA tools using text mining, and 


: : Reduce the s Tool is ready. 

machine learning. | : | eS 

Operational ə Waiting for GAC to enable automatic forwarding of Increased productivity and 
N Pressure and emails from the Mexico inbox to our cloud account. Mid to end of July 2021 accuracy of triage (not 
IRCC Mexico processes PRs from 48 : : r : iu ge ( 
: : Accelerate * The solution should be operational 1-2 weeks after quantified) 

countries and TRs from 15 countries. : 

processing GAC approves. 


The emails are a huge operational 
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Identify high-risk files for : 
verifications, building on July 2020  Improveinteg 
pilot. Because this pilot focuses on incr 


e rules with Legal / 


Increased integrity and fraud 


N; IRM Aug 1, 2021 


detection 


improving integrity, itis not effe 
expected that processing times will à 
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Accelerate 
olüutions Identify low-risk files in the inventory processing and 


ig the data to determine if it's feasible to 
create sufficiently strong rules to automate eligibility End of August 2021 
approvals 


Size of green bin it still 
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achievement 


s Initial results are promissing but the progress is slowed 
down by other priorities. 

* Working with the Journey Lab and IT to automate th 
process for uploading supporting documents to th 
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supporting documents to improve processing and 
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Issue 587564 - Access to a sub-folder in the SPSS server repository 


Assigned To: Kaur.Harpreet 

State: Closed 

Created Date: 05/28/2020 2:28 PM 
Description: 


Could we please ensure that the following persons have full access rights to the 
folder in the new repository? 
Thanks! 


Ahmad.Imran 
Haïfaf. Amine 
Son.David 
Tipenko.Elena 
Van.My-Phuong 
Haymes.Michael 


History 


05/28/2020 3:05 PM Nhan.Phuong: 
Harpreet, would you please look into this access in Thank you 


05/29/2020 1:58 PM Podeanu.Robert: 
Closing ticket 


A3489879_1-000002 
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Issue 613065 - Netezza Access - Bruno Afonso 
Assigned To: Lambier.Mark 

State: Closed 

Created Date: 09/10/2020 10:54 AM 


Description: 
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Could you please give Bruno the same access that Michael Haymes has in the Bruno is a new A2SC 
Data Scientist who will work with Mike and other Data Scientists on Watchtower. 


History 


09/10/2020 3:09 PM Lambier.Mark: 
DONE.. 


Bruno's Access: 


i 
ae. eer 
User Properties 


| Account Valid Unt: No lint 


Rowset mit ke 
Mo ord 
Mo mi 
None Maximum: None 


PUBLIC 


Michael's Access: 
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User Properties 


settings. SEEN AAA AA SBA NAAN BAS SA NEN EEN BESS SEN EI BASSAS EN EISSN EN EIEN NEN IDPP SIII NN EN EIEN NEN ESBS NEN EN ESSN EN EISEN EN ESBS SENN SSNS EIEN BIEN BENE 
Account Vee Unt: 
Rowset it 


Giuery breout: 


Session detrei 


Session pror y None Maxmum. None 
Resource allocation group: PUBLIC 


‘Group EE 


09/10/2020 3:22 PM Rizvi.Haider: 
Client has been notified. Closing ticket. 
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Bug 724864 - CLIENT: accessibility issues on Personal Info page (paper) 


Assigned To: Dupuis.Marcel 

State: Closed 

Created Date: 10/12/2021 10:27 AM 
Description: 


According to "WAVE® Web Accessibility Evaluation Tool" (Chrome extension), on the "Provide your personal information" 
page, there's two WCAG accessibility issues on "UCI" and "Application Number" fields 

error: Missing form label 

see screenshot "missing-labels.png" 


Test using Wave and Lighthouse for accessibility issues. 


History 


10/29/2021 5:19 AM Siddiqi.Zahid: 
@Lecierc.Eric Are there similar issues on the upload more documents page? 


10/29/2021 7:12 AM Leclerc.Eric: 
@SiacdiaiZzahia no other accessibility were found on paper app at the time of testing 


11/03/2021 9:26 AM Leclerc.Eric: 
a new issue was discovered by Marcel yesterday, a new story/bug was created as it's a different a11y issue on a different 


page. ref: Bug 731860: CLIENT: accessibility issues on Upload Documents page (paper) 
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Overview of Watchtower (WT) Risks and Mitigations 
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are Withheld pursuant to sections 
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Page 27 
is withheld pursuant to sections 


est retenue en vertu des articles 


16(1)(b), 16(1)(c) 


of the Access to Information Act 
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Pages 28 to / à 30 
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Government Gouvernement 
of Canada du Canada 


Algorithmic Impact Assessment 


Home > Open Government 


Algorithmic Impact Assessment Results 


Save f Choose File | No file chosen Start Again Link to GitHub project repository 


@ Information in the AIA is only stored locally on your computer, and the Government of Canada does not have access to the 
information you place into the tool. If you wish to keep your work, please save the data locally for future use. 


On this page 


e Impact Level 
e Requirements Specific to Impact Level: 
e Mitigation Measures 
e Questions and Answers 
o Project Details 
o Impact Questions and Answers 
o Mitigation Questions and Answers 


@ Impact Level: 2 Current Score: 35 Raw Impact Score: 35 Mitigation Score: 25 


Requirements Specific to Impact Level: 2 


Peer Review 


At least one of: Qualified expert from a federal, provincial,territorial or municipal government 
institution Qualified members of faculty of a post - secondary institution Qualified researchers from a 
relevant non - governmental organization Contracted third - party vendor with a related specialization 
Publishing specifications of the Automated Decision System in a peer - reviewed journal A data and 
automation advisory board specified by Treasury Board Secretariat 


Notice 


Plain language notice posted on the program or service website. 


Human-in-the-loop for decisions 


Decisions may be rendered without direct human involvement. 


Explanation Requirement 


In addition to any applicable legislative requirement, ensuring that a meaningful explanation is 
provided upon request for any decision that resulted in the denial of a benefit, a service, or other 


regulatory action. 


Testing A3745411_1-000040 


https://open.canada.ca/aia-eia-js/Results 1/9 
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Before going into production, develop the appropriate processes to ensure that training Gata is TESTEg ©? hors eme 
for unintended data biases and other factors that may unfairly impact the outcomes. Ensure that data 
being used by the Automated Decision System is routinely tested to ensure that it is still relevant, 
accurate, and up-to-date. 


Monitoring 


Monitor the outcomes of Automated Decision Systems on an ongoing basis to safeguard against 
unintentional outcomes and to ensure compliance with institutional and program legislation, as well 


as this Directive. 


Training 


Documentation on the design and functionality of the system. 


Contingency Planning 


None 


Approval for the system to operate 


None 


Link to the Directive on Automated Decision-Making Impact Level Requirements 


Mitigation Measures 
The following internal stakeholders have been consulted: 


A documented process is currently in place to test datasets against biases and other unexpected 


outcomes. 


Accountabilities for the design, development, maintenance, and improvements for the system have 
been assigned. 


The audit trail clearly identifies the authority or delegated authority as identified in legislation. 
The system records all the recommendations or decisions made by the system. 

All key decision points are identifiable in the audit trail. 

All key decisions points are linked to the relevant legislation, policy or procedure. 

The system's audit trail indicates all of the decision points made by the system. 


The system's audit trail can be used to help generate a notification of the decision (including a 
statement of reasons or other notifications) where required. 


The audit trail identifies which version of the system was used for each decision. 

The system's audit trail shows who the authorized decision-makers are. 

The system is able to produce reasons for its decision or recommendations when required. 
There is a process in place to grant, monitor, and revoke access permission to the system. 


There is a mechanism to capture feedback by users of the systems. A3745411_ 2-000041 
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There is a recourse process in place for clients that wish to challenge the decision. 
The system enables human override of system decisions. 


There is a process in place to log instances when overrides were performed. 


Questions and Answers 


Project Details 


Name of Respondent 
English Content : 
Steven Gonzalez 


French Content : 


3 


Job Title 
English Content : 


Assistant Director 


French Content : 


3 


Department 
Citizenship and Immigration (Department of) 
Branch 


English Content : 
OPPB 


French Content : 


RAR RAR RAR ARR E RS RSR RS RS SR RSR RSS ES EEE RE RAR R ART AA RA RNA AA NA RAS RARE ARR RAR NAR AT ARARE RAR E. 


Project Title 
English Content : 


Watchtower pilot 


French Content : 


Project Phase Points: 0 
Implementation 

Please provide a project description: 

English Content: 


AIA for administrative pilot of Watchtower on TR lines of business 


French Content : 


A3745411_3-000042 
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What is motivating your team to introduce automation into this decision-making process? 


(Check all that apply) 
e Improve overall quality of decisions 


e The system is performing tasks that humans could not accomplish in a reasonable period of 


time 
e Use innovative approaches 
Please check which of the following capabilities apply to your system. 


e Text and speech analysis: Analyzing large data sets to recognize, process, and tag text, speech, 


voice, and make recommendations based on the tagging 


e Risk assessment: Analyzing very large data sets to identify patterns and recommend courses of 


action and in some cases trigger specific actions 


e Content generation: Analyzing large data sets to categorize, process, triage, personalize, and 


serve specific content for specific contexts 


Impact Questions and Answers 


Is the project within an area of intense public scrutiny (e.g. because of Points: +3 
privacy concerns) and/or frequent litigation? 

Yes 

Are clients in this line of business particularly vulnerable? Points: +0 
No 

Are stakes of the decisions very high? Points: +0 
No 

Will this project have major impacts on staff, either in terms of their Points: +0 
numbers or their roles? 

No 

Will you require new policy authority for this project? Points: +0 
No 

The algorithm used will be a (trade) secret Points: +0 
No 

The algorithmic process will be difficult to interpret or to explain Points: +0 
No 

Does the decision pertain to any of the categories below (check all that apply): 

e Economic interests (grants and contributions, tax benefits, debt collection) Points: +1 
e Access and mobility (security clearances, border crossings) Points: +1 
Will the system only be used to assist a decision-maker? Points: +1 
Yes 

Will the system be replacing a decision that would otherwise be made by a Points: +0 
human? 

No 

Will the system be replacing human decisions that require judgement or Points: +0 
discretion? 

No 


https://open.canada.ca/aia-eia-js/Results 
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developed it? 

Yes 

Are the impacts resulting from the decision reversible? Points: +2 
Likely reversible 

How long will impacts from the decision last? Points: +2 
Some impacts may last a matter of months, but some lingering impacts may last 

longer 

Please describe why the impacts resulting from the decision are as per selected option 
above. 

English Content : 

Impacts are highest for SP and WP, where a client could miss a semester or a worker could miss a 
job opportunity. Impacts for TRV are lower. TRV far outnumber SP and WP combined. 


French Content : 


The impacts that the decision will have on the rights or freedoms of Points: +1 
individuals will likely be: 

Little to no impact 

Please describe why the impacts resulting from the decision are (as per selected option 
above). 

English Content : 

Foreign nationals do not possess a "right" to enter Canada. Impacts are better framed in terms of 
economic interests (see below) rather than "rights or freedoms." 


French Content : 


The impacts that the decision will have on the health and well-being of Points: +1 
individuals will likely be: 

Little to no impact 

Please describe why the impacts resulting from the decision are (as per selected option 
above) 

English Content: 

TR lines of business are generally not related to health of clients. It is rare that a client is seeking 
medical attention in Canada. 


French Content : 


The impacts that the decision will have on the economic interests of Points: +2 
individuals will likely be: 

Moderate impact 

Please describe why the impacts resulting from the decision are (as per selected option 


above) A3745411_5-000044 
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Missing a semester or a job opportunity could affect the financial situation of the client. But these 
cases are fewer in number than TRVs, where the impact on economic interests of the client is 


generally low. 


French Content : 


LL LL A A 


The impacts that the decision will have on the ongoing sustainability of an Points: +1 
environmental ecosystem, will likely be: 

Little to no impact 

Please describe why the impacts resulting from the decision are (as per selected option 
above) 

English Content : 

Not related to the environment 


French Content : 


$ 
$ 


Ë 
$ 
$ 


Will the Automated Decision System use personal information as input data? Points: +4 
Yes 

What is the highest security classification of the input data used by the Points: +3 
system? (Select one) 

Protected B / Protected C 

Who controls the data? Points: +1 
Federal government 

Will the system use data from multiple different sources? Points: +0 
No 

Will the system require input data from an Internet- or telephony-connected Points: +0 
device? (e.g. Internet of Things, sensor) 


No 
Will the system interface with other IT systems? Points: +4 
Yes 
Who collected the data used for training the system? Points: +1 


Your institution 

Who collected the input data used by the system? Points: +1 
Your institution 

Will the system require the analysis of unstructured data to render a Points: 0 
recommendation or a decision? 

Yes 

What types of unstructured data? (Check all that apply) 

e Audio and text files Points: +2 


Mitigation Questions and Answers 


Internal Stakeholders (Strategic policy and planning, Data Governance, Points: +1 
Program Policy, etc.) A3745411_6-000045 
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Yes 

External Stakeholders (Civil Society, Academia, Industry, etc.) 

No 

Do you have documented processes in place to test datasets against biases 
and other unexpected outcomes? This could include experience in applying 
frameworks, methods, guidelines or other assessment tools. 

Yes 

Is this information publicly available? 

No 

Have you developed a process to document how data quality issues were 
resolved during the design process? 

No 

Is this information publicly available? 

No 

Have you undertaken a Gender Based Analysis Plus of the data? 

No 

Is this information publicly available? 

No 

Have you assigned accountability in your institution for the design, 
development, maintenance, and improvement of the system? 

Yes 

Do you have a documented process to manage the risk that outdated or 
unreliable data is used to make an automated decision? 

No 

Is this information publicly available? 

No 

Is the data used for this system posted on the Open Government Portal? 
No 

Does the audit trail identify the authority or delegated authority identified 
in legislation? 

Yes 

Does the system provide an audit trail that records all the recommendations 
or decisions made by the system? 

Yes 

Are all key decision points identifiable in audit trail? 

Yes 

Are all key decision points within the automated system's logic linked to the 
relevant legislation, policy or procedures? 

Yes 

Do you maintain a current and up to date log detailing all of the changes 
made to the model and the system? 

No 

Does the system's audit trail indicate all of decision points made by the 
system? 

Yes 
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Can the audit trail generated by the system be used to help generate a 
notification of the decision (including a statement of reasons or other 
notifications) where required? 


Yes 

Does the audit trail identify precisely which version of the system was used Points: +2 
for each decision it supports? 

Yes 

Does the audit trail show who an authorized decision-maker is? Points: +1 
Yes 

Is the system able to produce reasons for its decisions or recommendations Points: +2 
when required? 

Yes 

Is there a process in place to grant, monitor, and revoke access permission Points: +1 
to the system? 

Yes 

Is there a mechanism to capture feedback by users of the system? Points: +1 
Yes 

Is there a recourse process established for clients that wish to challenge the Points: +2 
decision? 

Yes 

Does the system enable human override of system decisions? Points: +2 
Yes 

Is there a process in place to log the instances when overrides were Points: +1 
performed? 

Yes 

Does the system's audit trail include change control processes to record Points: +0 
modifications to the system's operation or performance? 

No 

Have you prepared a concept case to the Government of Canada Enterprise Points: +0 
Architecture Review Board? 

No 

Have you completed a Privacy Impact Assessment or revised an existing Points: +0 
one? 

No 

Does your system reflect Privacy by Design principles? Points: +0 
No 


Export English Document Export French Document 


> English Content 


> French Content 


Date modified: 2020-06-03 


https://open.canada.ca/aia-eia-js/Results 


A3745411_8-000047 


8/9 


$ Immigration, Refugees Immigration, Réfugiés 
and Citizenship Canada et Citoyenneté Canada 


Information disclosed under the Access to Information Act 


11/30/2020 Algorithmic Impact Assessment - Évaluation de l'Incidence Algorithmique 


Ve rsion: 0.8.1 L'information divulguée en vertu de la loi sur l'accès à l'information 


A3745411_9-000048 


https://open.canada.ca/aia-eia-js/Results yy 


fi wf Immigration, Refugees Immigration, Réfugiés 
and Citizenship Canada et Citoyenneté Canada 
Information disclosed under the Access to Information Act 
L'information divulquée en vertu de la loi sur l'accès à l'information 
Immigration, Refugees Immigration, Réfugiés 
and Citizenship Canada et Citoyenneté Canada 


Director General Directeur général 
Integrity Risk Orientation sur les 
Management risques pour l'intégrité 
Ottawa K1A 1L1 
F- 07790719 
PROTECTED B 


MEMORANDUM TO THE DIRECTOR GENERAL, OPERATIONAL PLANNING AND 
PERFORMANCE BRANCH AND THE DIRECTOR GENERAL, INTEGRITY RISK 
MANAGEMENT BRANCH 


GOVERNANCE AND BUSINESS OWNERSHIP OF LIGHTHOUSE TOOL 


FOR APPROVAL 


SUMMARY 


This memorandum seeks your approval of the Lighthouse Governance Framework (‘the 
Framework’) to ensure agreement on shared ownership and responsibility. 


The Framework provides oversight on the management of the Lighthouse tool and outlines 
accountabilities, roles, and responsibilities for its development, implementation and use. 
Business ownership of Lighthouse will be shared between the Operational Planning and 
Performance Branch (OPPB) and Integrity Risk Management Branch (IRM). 


Lighthouse is an Al-based risk indicator solution that has been developed to automatically 
and comprehensively extract risk and fraud patterns from source data from the Global Case 
Management System for any applicable line of business. The tool does not involve 
automated decision-making. 


We recommend that you approve the Lighthouse Governance Framework and its business 
co-ownership by signing the approval page within the Framework as well signing this 
memorandum by August 18, 2021. 


BACKGROUND: 


e In recent years, the demand for artificial intelligence (AI) solutions to assist with the 
Department’s program delivery has been steadily increasing, primarily to address challenges in 
volume management. In April 2020, the Treasury Board Secretariat’s Directive on Automated 
Decision-Making came into force to outline high-level requirements for automated solutions in 
the Government of Canada. In June 2019, IRCC also developed its own internal Policy 
Playbook on Automated Support for Decision-Making. 


Canada 
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e Formerly known as Watchtower, Lighthouse is an Al-based risk indicator solution that has 
been developed to automatically and comprehensively extract risk and fraud patterns from 
source data from the Global Case Management System for any applicable line of business. It is 
a data-mining tool that identifies and presents fact-based information. The tool’s findings can 
be configured to produce customized reports to satisfy various needs for Risk Assessment Units 
within the integrated processing network, allowing them to direct their resources to potential 
cases of concern. This will assist Risk Assessment Units with investigations and large-scale 
trend analysis, and lead to efficiencies in the identification and processing of higher-risk cases. 


e Lighthouse does not make recommendations or render administrative decisions about clients or 
their applications. Since all eligibility and admissibility decisions will be made by decision 
makers and the tool would not be involved in making any decisions, an Officer of Record 
would not be required to act as the authority under the Instrument of Designation and 
Delegation. Measures have been taken to ensure that human intervention is part of every stage 
of the tool’s application. 


e In its initial pilot, which ran in summer 2020 on the caseload of global study permit 
applications, Lighthouse uncovered over 800 unique risk patterns, some of which led to 
identification of larger-scale fraud trends. By using the tool’s full potential and focusing our 
risk management efforts where attention is needed most, the Operations Sector can potentially 
create processing efficiencies in cohorts that do not require as much effort. 


e A governance framework (in annex) has been drafted to set priorities for Lighthouse’s use, 
explain its processes, outline related roles and responsibilities, and ensure transparency in the 
usage of the tool. 


CURRENT STATUS: 


e Fach usage of the tool that involves live applications requires a dedicated project charter to 
complement the Framework by addressing the specifics of the usage in question. By having a 
broader framework, the general principles of the tool on its usage and governance can be 
agreed upon in advance which, when supplemented by specific project charters, would 
facilitate procedures and expedite implementations. 


e Business ownership of Lighthouse will be shared between OPPB and IRM, given each branch’s 
mandate and the potentially broad scope of the Lighthouse project. The responsibility of 
development, implementation and maintenance of the tool will lie with the Advanced Analytics 
Solutions Centre team within OPPB. The team will focus on the tool’s technical design and 
record-keeping as it relates to the design and configuration data of the tool, ensuring that the 
privacy and legal requirements and recommendations are followed. IRM will be responsible for 
operationalizing the program-level aspects of the tool’s findings as well as maintaining 
administrative aspects of the tool, such as quality management and ensuring the governance 
framework remains evergreen. IRM will also lead working group meetings to bring forward 
any necessary changes, in order to respond to departmental priorities or changing risk 
management practices and develop a consistent approach for the department. 


A3745412_2-000050 
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e CDO will play a key role in overseeing the tool’s data management. CDO will seek approval 
on data inputs specific to each implementation or pilot from the Data Executive Steering 
Committee (DESC), who will in turn inform Issues Management Committee (IMC). 


e The processing networks (IN, CN, and DN) and their Risk Assessment Units will 
operationalize case specific aspects of the tool’s findings, and work with IRM and OPPB to 
map out operational processes and to improve its effectiveness and usage. Case Management 
Branch will assess larger-scale fraud trends flagged by the tool and ensure resulting business 
intelligence is shared with all other stakeholders. 


e Strategic and Program Policy Branch will be responsible for providing guidance on policies, 
including Algorithmic Impact Assessments, and for coordinating engagement with other 
stakeholders and the public. 


e Stakeholders such as Migration Health Branch, Citizenship and Passport Programs Branch, and 
Transformation and Digital Solution Sector (TDSS) may participate in Lighthouse working 
groups in the future, should the tool’s involvement become relevant to their respective 
mandates. 


e This division of roles reflects the approach presented to the Issues Management Committee in 
December 2018, and aligns with the 2018-2023 Operations Sector Strategic Plan. 


CONSULTATIONS: 


e The Framework has been developed in close collaboration with key partners. Approval was 
obtained at the Director level from Operations Planning and Performance Branch, Integrity 
Risk Management Branch, Centralized Network, International Network, Domestic Network, 
Immigration Program Guidance Branch, ATIP Division, Legal Services Unit, Strategic Policy 
and Planning Branch, Case Management Branch, Admissibility Branch, Internal Audit and 
Accountability Branch, and Chief Data Officer. 


RECOMMENDATION(S): 


e We recommend that you approve the Framework and its business co-ownership by signing the 
approval page within the Framework document as well as in this memorandum. 


NEXT STEP(S): 


e Following your approval, the Framework will be applied to the operational environment 
starting in fall 2021. 


e The second global study permit pilot, which was initially scheduled to run from March to 
September 2021, is currently in its early consultation phase. Representatives from IRM, OPPB, 
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CN, DN, and IN are meeting weekly, reviewing patterns mined by the tool, and agreeing on 
procedures. 


e-approved 
Elizabeth Stronach 
Director, Integrity Risk Management Branch 


e-approved 
Steven Gonzalez 
Director, Operational Planning and Performance Branch 


Alain Desruisseaux 
Director General, Integrity Risk Management Branch 


LJ I concur 


L] I do not concur 


Marie-Josee Dorion 
Director General, Operational Planning and Performance Branch 


LJ I concur 


L] I do not concur 


Annex: Governance Framework for Lighthouse 
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Integrated Networks Steering Committee 


Record of Decision 
May 13, 2021 


| Please send comments by Friday COB or the RoD will be considered approved 


Objectif: To seek committee endorsement to begin the pilot to test the use of the tool in improving program integrity and fraud 
detection efficiency in the global SP caseload. OPP is also seeking a decision regarding the ownership of the program 


Documents: 


Watchtower LH_INSC_QnATalking 
Integrated Network Si Points.docx 


Roundtable: 

e IN confirmed their support for this pilot and moving forward to the Data Steering Committee. IN would like to have lighthouse 
brought back to INSC for endorsement of future phases. 
IN is interested in assisting OPP’s Advanced Analytics team in moving toward more consistent reporting on trends, ground 
intelligence and external information to identify risks for this tool so: 


IRM offered support for this pilot 

CN gave support for this pilot and IN’s proposal to include external data where possible. CN requesting to add building a 
communications plan and meeting with the bargaining agents to the next steps 

IPG is fully supportive of the pilot and tool. They too support IN’s suggestion to build upon the tool with ` "in order 
to strengthen program integrity. 

OPP supports the idea of incorporating external factors/trends in order to rely less upon self-declared information 

In terms of ownership, OPP notes that an Officer of Record Memo would not be required for this scenario given the tog! does 
not make decisions, but we need someone to greenlight the pilot. 


Decision: The table endorses moving forward with the lighthouse SP Pilot 


Next steps: 

e OPP to bring this item forward to the Data Executive Steering Committee scheduled for late May 
e To determine the business owner and ensure clear accountabilities 

e OPP to brief management teams and bargaining agents 
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IPG: 
e IPG to schedule a meeting with network DGs to ensure clear and consistent approach to processing TR and PR for India/Pakistan 
OPP Update on CEC Rounds: 
There continue to be concerns around CRS scores; therefore, a smaller round will be conducted this week than originally 
planned. Instead of the 6,000 round we will be doing roughly 4200. This will be reviewed on a weekly basis until our inventory 
with CRS scores over 400 replenishes 
To note this could mean the next 12 rounds could be lower than anticipated making it more difficult to reach targets 
This discussion will be brought to the next LPPC 


Blair Haddock OPPB Yes 


fIsabelleDaoust | CMB es S 
pAndreBaril PG es G 
Sylvain Beauchamp | CEB No | CynthiaRebaza | 
Peter Mielke | OPPB-DART Vs 
Alain Desruisseaux | IRM es G 
CraigShankar | MHB es G 
Tara Davidson LCN es G 
Alexandra Hiles | DN Nes 
Maxine O [CPP es G 
Sean McNair Nes G 
Jean-Marc Gionet | RASO o es G 
Brittany Doyle | Secretariat, Vs 


on 
Julia Gurr-Lacasse IN 


naan Barry IPG 
Kevin Terry 


No 
Elizabeth Snow IN 
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Built in-house and is readily adaptable to other IRCC business lines 


System can scan for almost all forms of data-detectable risk patterns, and be configured for 
specific risk types (e.g., misrep, organized crime, etc.) or countries 


Able to identify new risk patterns, thus enabling Risk Assessment Units (RAUs) to proactively 
select cases for verifications, based on previous indicators 


Enables RAUs and investigative teams to be more efficient and effective in identifying, 
validating and taking action on fraud and risk patterns 


Can contribute to improving processing speed of bona-fide applications 


Cost avoidance from fewer adverse events (e.g., each asylum claim costs the federal 
government roughly $16,000) 


Dovetails with existing intelligence-based risk detection approaches 


Modest costs for development and maintenance. Immediately deployable using existing 
infrastructure 
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System provide neutral, factual information to increase evidence available to officers 


e Lighthouse only provides information to support RAO decisions about when to 
collect additional evidence. 


e No decision automation. 
e All data used by the system originates from GCMS 


The pilot is designed to avoid fettering 


e Lighthouse information is only provided to risk assessment units for their 
consideration; adjudicating officers will not see Lighthouse pattern information and 
will not be informed which applications are involved in the pilot. 
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Lighthouse Live Pattern/Match 
Review Session 


September 1, 2021 (CN/DN) 
Sept 3, 2021 (IN) 
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Agenda 


TRUSE tok & Updates 
Questions from Intro Meeting? 
e ADM Presentation 
e Target Launch Date for soft launch start: Week of Sept 13, 2021 


e User Manual Developed 
(nites://ecdocs2 .cl.ec.ca/otcs/cs.exe/link/41 4438882 


e Project Team Plans for interaction (IN, CN/DN, Project Steering) 
e Planning: Charter Updates, Assessment Framework 


e Pattern Report Details 
e Group inspection of a few matches 


Part 2: Group Preparedness Discussion 
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Key Questions 


Comfort Level - Tool Usage 
e How comfortable is the team with usage of the tool? 


Comfort Level - Pilot Design 
e How comfortable are users with the process as proposed and the start date of Week of Sept. 13, 2021? 


Resource Availability 
e Is it anticipated that resources will be available to support throughout the pilot? 
e Do users need additional support to justify and brief upward on the project or their participation? 


Preparedness 


e Are there any additional considerations relating to panning, documentation, consultation, process 
definition, etc., which should be covered pre-launch? (e.g., assessment criteria) 
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BIAS 
ASSESSMENT 


Prepared by: 
Advanced Analytics Solutions Centre (A2SC) 


Date: 2021-06-15 
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1. Purpose 


The purpose of this document is to make an initial assessment of the potential for bias under the 


Lighthouse Risk Identification System 


2. Context 


In the case of Lighthouse, which is designed to augment human decision making by identifying and 
summarizing possible historical patterns of concern, so that IRCC officers can make informed 


decisions about when additional scrutiny of an application may be required. 


In the context of this project design, the primary focus of interest is on reducing the impact of “false 
positive” scenarios. In the context of the Lighthouse pilot, a false positive event occurs when a new 
applicant to IRCC matches against a historical pattern of concern identified by the lighthouse 
system. This event triggers a summary of this pattern to be shown to a Risk Assessment Officer, 
who assesses the pattern of concern summary, as well as the new application, to make a 
determination if additional information should be collected to ensure that supporting documentation 


submitted with an application is genuine and accurate. 


This is important as the core 
reason for assessing bias for Lighthouse is to ensure that specific groups of individuals are not 


disproportionately impacted by the system. 


3. Design Mitigation Considerations 
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In developing the Lighthouse project, the Lighthouse Project Team has identified a pilot design that 
is intended to negate or greatly reduce any possible harm to any individual applicant that 1s not 
engaged in fraud or misrepresentation on their application. Put another way, the system is designed 
to reduce the human impact of a false positive to very close to zero. This design has important 
considerations as it relates to any potential system biases, as the core interest in bias assessment 1s to 
ensure that the system is not creating negative impacts that are disproportionately concentrated on a 
single demographic group. As designed, the system is intended to only impact true positive cases, 
i.e., applications that have been verified by a third-party as having submitted fraudulent 


documentation to support their application. 


3.1. Mitigation 1: “Do No Hatm” Design 
Without proper mitigations, there are two clear ways that individuals who are not engaged in fraud 
on their applications could be negatively impacted by the system. These are the aforementioned 
false-positive cases. 
a) Processing Delays: Without proper mitigations, the time it takes to verify with a third-party 
that a student is genuine could lead to delays in the processing of that person’s applications. 
In the context of bias assessment, this could manifest itself in creating systematically longer 
processing times for women than men, for example. 
b) Refusal Likelihood: Without mitigations, the Lighthouse system could create situations 
where individuals belonging to certain demographic groups may be systematically more likely 


to be refused, disproportionate to their actual underlying risk 


Mitigating Processing Delays: 
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3.2. Mitigating Refusal Likelihood: 

A mote important risk to mitigate is the possibility that a legitimate applicant, who is not engaged in 
fraud or misrepresentation, is identified by the Lighthouse system and that merely by virtue of being 
identified by the system, they are viewed by officers as higher risk. This can result in a fettering of 


officer decisions and a negative impact on the client via a reduced likelihood of being approved. 
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This risk is mitigated in two ways. The first is to ensure that no information from lighthouse is ever 
used directly in front-line decision making. The second is by blinding the front-line officer to the 


fact that Lighthouse identified a possible concern on this application. 


3.2.1. Lighthouse Information is never used directly in decision making and it does not 
automate decisions 


As designed, Lighthouse provides information to. 


. This information takes the form of a neutral summary of a historical pattern of concern 
that matches the current application that has been received. This information performs only one 
purpose, which is to support a decision about whether additional validation of the applicants 


information should be performed. 


information about past 
applications that identified the historical pattern of concern are never used as evidence in 
adjudicating a client’s application. That is, there is no extrapolation of facts from past applications 
to the current application under consideration, only verified evidence about the application under 


consideration is used in the adjudication. 


2.2. Mitigation of Decision Fettering 

To ensure that Lighthouse pattern information is not inadvertently influencing application decisions, 
a separation is used between the Risk Assessment Officers (who assess Lighthouse information and 
decide if a verification should be performed on an application) and the Front-Line Officers who 
assess applications directly. The Front-Line Officers are not given access to Lighthouse 
information and are blinded to which applications have been identified by Lighthouse. This way, 
while Lighthouse may provide evidence about past fraud trends to help support the decision to 
verify facts of an application; it is ultimately the results of that third-party verification which are the 


sole piece of information made available to the front-line deciding officer. 


Figure 1 visually describes the Lighthouse pilot design and these mitigation measures. 


A3745421_5-000080 


RER 


$ Immigration, Refugees Immigration, Réfugiés 
and Citizenship Canada et Citoyenneté Canada 
s.1 6(1 )(b) Information disclosed under the Access to Information Act 
L'information divulquée en vertu de la loi sur l'accès à l'information 


s.16(2)(c) 


Figure 1: Pilot Design for Lighthouse 
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4. Quantitative Assessment of Bias 


In the context of the SP pilot for Lighthouse, we believe that the previously noted mitigation 
measures greatly reduce any potential for the system to negatively impact any applicant that is not 
engaged in fraud. This is important context for bias assessment, as it is the systemic and uneven 
distribution of such negative impacts that are the primary measure of interest when assessing bias in 


a system such as Lighthouse. 


Approach 

To evaluate the historical bias assessment, Lighthouse was trained to identify patterns of concern on 
799,000 student permit applications received by IRCC between January 1, 2019 to December 31, 
2020 (training set). To support this bias assessment, the patterns identified in the training set were 


used to assess possible matches on an additional 276,000 applications received between January 1, 


2021 and July 2, 2021 (test set). 


Assessing Bias 
Risk of fraud in IRCC applications is not evenly distributed amongst genders, age groups, or 


geographic regions. As such, it should not be expected that applications matching against historical 


risk patterns should be equally distributed among these same factors. Rather, it would be expected 
that the distribution of applications identified by the system as matching a historical pattern should 
roughly align with the underlying distribution of the known adverse applications in the historical 
data record. So, for example, in the training data assessed, men were 91% more likely than women 
to have an adverse verification on file, and were similarly 87% more likely than women to be 


identified as matching a historical pattern. 
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Gender Distributions 
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Males made up about 56% of student 


permit applications 


~ PO ae aaa GR -~ i ~ Cl "o . x `“ CE ae et A ~ = = = 


A3745421_8-000083 


Immigration, Refugees Immigration, Réfugiés 
it de i and Citizenship Canada et Citoyenneté Canada 
s.1 6(1 )(b) nermation PoE RA under the Access $ Information ASI 
L'information divulguée en vertu de la loi sur l'accès à l'information 
s.16(2)(c) 


A3745421_9-000084 


s.1 6(1 )(b) it ay i Immigration, Refugees Immigration, Réfugiés 


and Citizenship Canada et Citoyenneté Canada 
s.1 6(2)(c) Information disclosed under the Access to Information Act 
L'information divulquée en vertu de la loi sur l'accès à l'information 


Country of Residence Distributions 


and similarly make up a large percentage of Lighthouse pattern match cases. The large 
number of countries that applicants reside in means that it is relatively unlikely to get an extremely close distribution between the matches produced by 


lighthouse and the underlying adverse distribution in these countries. However, a relatively close match was obtained, with the exception of some notable 


outliers. 


. As a result, it appears that 
despite the high number of Lighthouse-matched applications relative to the baseline sample, the system does appear to have identified a growing fraud 
trend in this country that 1s being independently validated by the existing manual risk assessment work. As such, the system appears to be operating as 


intended. However, these trends will continue to be monitored closely throughout the pilot. 
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Age Distribution 


Lighthouses matches by age distribution very closely track to the baseline adverse distribution in the baseline population. Of note, individuals aged 26-35 


may be slightly underrepresented relative to their share of adverse, but these appear to be within reasonable margins. It is worth noting that while 


these individuals will be excluded from 


output during the pilot and will not be included in the system output reports provided to Risk Assessment Officers. 
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5. Summary 


Overall, this bias assessment did not find significant evidence of bias in the outputs of Lighthouse patterns, and that 


Lighthouse matches relatively closely reflect underlying risk patterns present in the data. 


It is important to note that any expected impact in terms of bias in the outputs of Lighthouse 1s expected to be 
greatly diminished or fully negated by the various mitigations discussed in this report. Most importantly, the pilot 
has been designed to ensure that any individual not engaged in fraud, even if identified by a match against a 


Lighthouse identified pattern of concern, should not be negatively impacted in any way. 
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Built in-house and is readily adaptable to other IRCC business lines 


System can scan for almost all forms of data-detectable risk patterns, and be configured for 
specific risk types (e.g., misrep, organized crime, etc.) or countries 


select cases for verifications, based on previous indicators 


Enables RAUs and investigative teams to be more efficient and effecti 
validating and taking action on fraud and risk patterns 


Can contribute to improving processing speed of bona-fide applications 


Cost avoidance from fewer adverse events (e.g., each asylum claim costs the federal 
government roughly $16,000) 


Dovetails with existing intelligence-based risk detection approaches 


Modest costs for development and maintenance. Immediately deployable using existing 
infrastructure 
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System provide neutral, factual information to increase evidence available to officers 


e Lighthouse only provides information to support RAO decisions about when to 
collect additional evidence. 


e No decision automation. 
e All data used by the system originates from GCMS 


The pilot is designed to avoid fettering 


e Lighthouse information is only provided to risk assessment units for their 
consideration; adjudicating officers will not see Lighthouse pattern information and 
will not be informed which applications are involved in the pilot. 
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Engaged Stakeholders 
International Network (IN) 
Domestic Network (DN) 
Centralized Network (CN) 
Integrity Risk Management (IRM) 


Immigration Program Guidance (IPG) 


Legal Services (Department of Justice/LSU) 
Privacy (ATIP) 


Strategic Planning and Performance (SPP) 
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e A2SC goes to great lengths to ensure that Lighthouse is developed responsibly and does not 
introduce bias. 


e Steps include: 
1. External review of Lighthouse by Statistics Canada 
2. Following best practices in data science to avoid bias and active monitoring of risk indicators 
3. Many layers of human review of the risk patterns to eliminate incremental bias 
4. Overall design centred on the interests of the client to avoid causing harm 
5. Active engagement with external stakeholders, including governance exercise in Winter 2020 


6. Follow the comprehensive ethics framework to govern AA work 
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Background 


In Canada, privacy is considered a human right. As the majority of the data we handle at 
IRCC is personal information, privacy requirements must be top-of-mind when planning, 


developing and monitoring any initiative involving data-driven technology. 


This document is intended to outline the ptivacy protections in place for this 
patticular model or tool. The requirement statements in this document are based off the 


Baseline Privacy Requirements for Disruptive Technology that lays out the minimum privacy 


requirements that must be met for all initiatives involving disruptive technology. 


This document does not replace the need for a Privacy Impact Assessment (PIA) as it 1s 
intended only to analyze privacy compliance at a model level and document steps taken to 
increase privacy protections. This document may be used to assist in completing a larger 
initiative or program-level privacy assessment as required. Program areas are responsible for 
filling out a Privacy Needs Assessment (PNA) and sending it to the ATIP Division. 


Information about the PNA and the template can be found on Connexion. 


Details 


Version 1.0 Model Privacy 


Assessment is completed: 


Update MPA whenever the Model or Tool is updated 
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Model Privacy Assessment 
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Model or Tool Update 
Date: 


Version 2.0 Model Privacy 


Assessment completed: 


Summary of Initiative 


What is the problem this model is trying to solve? Why is this the best solution to that 
problem? Why is the use of personal information necessary? What does the model do? What 
is the population the model is being applied to (ex: study permit applicants from a specific 


country)? In what way does the model support officers in making decisions? Does it suggest 


decisions for officers? Please include any and all useful information. 


Summary of Initiative 

Lighthouse is a prototype risk detection tool developed by IRCC’s Advanced Analytics 
Solution Centre (A2SC). The tool aims to enhance program integrity and Canadian public 
safety by automatically identifying and summarizing historical risk patterns for IRCC 
officials. The tool aims to provide neutral, fact-based risk information to IRCC officials, 
augmenting their capacity to quickly identify and understand organized fraud trends and 
other risk patterns. It can be used to support frontline decision makers or to understand 
historical risk patterns. Lighthouse presents opportunities for the department to 
modernize IRCC’s risk assessment activities by placing timely and relevant risk 
information at the fingertips of IRCC officials in a manner that was previously impossible 


ot prohibitively expensive to do. 
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High-Level Summary of How the Model Works (as appropriate, include: how the 


rules are created, how an application runs through a model/how personal information is 


used in production, an overview of the output/what officers see, etc.) — 
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Requirements 


Legal Authority 


A program must have the parliamentary authority to collect and use personal information for 
the specified purposes of the program. This legal authority will be identified in the Privacy 


Needs Assessment and other required privacy assessments for this initiative. 


A program must also be legally allowed to use disruptive technology and/or automation to 
support the program. Identify which of the legal authorities below grant your program area 
the authority to administer your program(s) using electronic means (disruptive 


technology): 
Part 4.1 of the Immigration Refugees Protection Act 


O Section 2.2 of the Passport Order 


Accountability 


A part of ethical and responsible development and deployment of advanced analytics, 
artificial intelligence and automation initiatives is ensuring that humans are ultimately 


responsible for the model’s behaviour. Describe below the processes to guarantee that 
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model rules are reviewed by humans and to make sure that internal governance and 


accountability (sign-off) processes are in place. 
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Source of Data 


Personal information must only be collected if it relates directly to an operating program or 
activity of IRCC and each personal information data element must be necessary to the 
administration of the program. When possible, personal information should be collected 


directly from the individual. 


For the purposes of disruptive technology initiatives, only information found in 
departmental systems of record (ex. GCMS) should be used unless another data source 
has been approved by IT Security, and the activities of training models and algorithms 
should be done outside of those systems of record. Data collected from outside sources 


should not be used unless demonstrably necessary, and proper information sharing 
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agreements, memoranda of understanding, service level agreements etc. should be in place 


and followed. 


If outside data is used, 
through what means is it 
collected (ex: MOUs, ISAs, 
etc.) 

Demonstrate how Necessity, 
Proportionality, Effectiveness, 


and Minimal Intrusiveness, 


: ering what data to 


the model (Oakes Test). 
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Notice / Informed of Purpose / Transparency / Explainability 

IRCC must notify individuals (clients and the general public) of the purpose for which their 
information is being collected, commonly referred to as a ‘privacy notice.’ This notice must 
be given at or before the time of collection. IRCC must notify past applicants that their 
information was used to train or build models. Individuals have a right to know exactly how 
their personal information was processed through a disruptive technology system. Ensuring 
that plain language explanations are available on demand would allow individuals to see how 


technology was used to support decision-making. 


notified about the use of this model and how the use of disruptive technology will be 
explained to applicants. 
Notice at time of collection The privacy notice on the Study Permit forms a well as 
(link to the privacy notice if the corresponding Personal Information Bank (PIB) have 
applicable) been updated to account for the use of analytics. 

The Digital Transparency webpage that is now published 


accounts for the use of risk screening tools such as 


Lighthouse by explaining that advanced data analytics 


systems will be used by IRCC to recognize patterns to 
help accelerate our work and better inform decision 


makers. 
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Explainability of the model The pattern reports that are used in Lighthouse are 


(link to the plain language intended to provide sufficient evidence of any individual 


explanation) pattern. All patterns are “self-contained” in that they are 


intended to stand on their own metit regardless of the 
rest of the system. Encrypted data and model 
information is currently being retained to allow A2SC to 
recreate a model on-demand and provide the underlying 
data to explain how Lighthouse patterns were produced 


and why applications matched against these patterns. 


Accuracy 
IRCC must take all reasonable steps to ensure that personal information used for an 


administrative purpose is as accurate, up-to-date and complete as possible. This also 


includes ensuring there are mechanisms to correct inaccurate information. 


For initiatives involving disruptive technology, this involves ensuring data 1s collected from a 
reliable source, the quality of the data, developing technological mechanisms to make certain 
that the technology is working (such as feedback loops and blind tests), quality assurance on 


the outputs, and so on. Additionally, to guarantee the accuracy of the data, program areas 


must take the necessary steps to minimize unintended bias in the data. Finally, accuracy also 
involves model maintenance and ensuring the model is trained and re-trained on the most 


updated, accurate and reliable data. 


 Accuracy — Ways the model is ensuring accuracy of the data and outputs, and the process _ 


to correct inaccuracies. Describe any Quality Assurance (QA) processes that are in place. 


Privacy, Policy and Governance Unit, ATIP Division | June 2021 | Version 1.0 — Final 
12 


A3745437_12-000168 


Immigration, Refugees Immigration, Réfugiés 
fi + il and Citizenship Canada et Citoyenneté Canada 
Information disclosed under the Access to Information Act 
L'information divulquée en vertu de la loi sur l'accès à l'information 


A s.16(1)(b) 
Model Privacy Assessment 


Lighihouse — Study Permit Piot #2 


s.16(2)(c) 


Version 1.0 Final ~ May 2021 


Use 


Personal information must only be used for the purpose it was initially collected, a use 
consistent with that purpose or for a purpose for which it is may be disclosed under section 


8(2) (see Disclosure, below). 


Applying disruptive technology to a dataset involving personal information is a use; 
this includes all uses whether administrative ot not. Personal information must be treated 
appropriately regardless of the level of automation or support the technology is providing. 
The use of disruptive technology should be a consistent use of the personal information. To 
determine what constitutes a consistent use of personal information, the original purpose 
and the proposed purpose must be so closely related that the individual would expect that 


the information would be used for the consistent purpose, even if the use is not spelled out. 
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Use — Mechanisms that are in place to reduce the inappropriate use of the data 


completing this assessment) 


Data minimization (only use data 
elements that are absolutely 


necessaty) 


De-identification 


(masking /hashing/synthesizing 
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data so that it’s no longer 


personally identifiable) 


Need to Know (ensuring access 


is only granted to those who need 


to know it) 


Other (Ex: Use of privacy 
enhancing technologies, 
anonymizing data for all 


demonstrations, etc) 


Disclosure 
Personal information under IRCC’s control must not be disclosed to anyone or any 


organization fot any teason, except for those reasons listed in sub-section 8(2) of the 


Privacy ct. 
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For initiatives involving disruptive technology, this includes information found in 
departmental systems of record (ex. GCMS) that other organizations such as CBSA or CSIS 
can view. Regular information sharing may continue to occur between IRCC and partner 
organizations, however Memoranda of Understanding (MOUs), Information Sharing 
Agreements (ISAs) and other formal agreements must be updated and modified through the 


appropriate channels if there 1s the desire to disclose outputs on a regular basis. 


Disclosure — Mechanisms that are in place to reduce the risk of inappropriate disclosure 


of the data, outputs and other model-related personal information. List GC partners and 
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Safeguards 

Personal information must be safeguarded appropriately regardless of the kind of technology 
applied to it. Appropriate administrative, technical and physical safeguards should be 

applied to personal information at all stages of a disruptive technology initiative, and 


consideration should be given to reducing the likelihood of privacy and security breaches 


throughout development. 


Safeguards — Safeguards that are in place in and around the model to protect the data 
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Retention and Disposal 


Personal information used for an administrative purpose (as a part of a decision-making 
process that affects the individual) must be retained for at least two years, and in accordance 


with the appropriate Retention and Disposition Schedule. All data (with the exception of 


training data in the Exploration Zone) must be kept such that in the event of a complaint or 
legal action, the decision can be replicated. The data in the Exploration Zone that 1s an exact 
duplicate of production data and that is used to generate and retrain model rules can be 


considered transitory. 


Retention and Disposition schedules 


Training Data in EZ 


Client Input Data (during 


_ Model Outputs 
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Model (the code) 


> 


Reports (outputs for officers 


legal tables, others as 


appropriate) 


Monitoring Plan 


Monttoring for privacy compliance to the above-noted requirements should be built in from 


the model development phase and a monitoring schedule post-deployment should be 


followed. 


In addition to being certain that the disruptive technology is working properly, here 1s a list 
of non-exhaustive monitoring activities to plan for: 

e Collection: Make sure no data from sources other than departmental systems of 
record (ex. GCMS) and other IRCC data repositories are included in the disruptive 
technology, and if there is outside data, put in place the appropriate ISA or MOU 
and keep these up to date. 

e Notice: Review privacy notices and transparency and explainability practices for 
accuracy and for current information. Update when required. 

e Retention and Disposal: Review the retention and disposal practices and ensure 
that no information 1s retained beyond IRCC’s prescribed retention period. 

e Accuracy: Build in regular data quality practices to ensure data 1s accurate, up to date 


and as complete as possible, and modify the information when required. 
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e Use: Review data handling practices, ensure mitigation measures against 


inappropriate use are functioning properly, employ new measutes as required, and 
update practices periodically. 

e Disclosure: Review disclosure practices so that disclosures are occurring as a part of 
up to date MOUs and/or ISAs, and ensure other government organizations can only 
see information they are permitted to see in GCMS under those MOUs/ISAs. Make 


modifications when required. 


e Safeguards: Complete the mandatory FE Security Assessment and Authorization 


process and conduct security checks to confirm that the training data, the technology 


itself and the outputs are secure. 


describe the steps you will follow to develo stablish the required monitoring plan. 
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Version 1.0 Final ~ May 2021 


Monitoring Notes: 

The quality assurance and monitoring plans will monitor the ongoing efficacy of the model 
and of the data quality. The quality assurance and monitoring activities will contribute to 
monitoring the Accuracy and Use privacy requirements. At the time of completing this 
document, a detailed plan to monitor all of the privacy requirements was not in place. 
However, the measures that are in place should mitigate many potential privacy risks in the 
future (such as encrypting data, limiting access to only those with a ‘need to know’ etc.) This 
model will be in a pilot mode from June 2021 to October 2021, and many assessments will 
take place during that time. Building in additional privacy controls may occur during the 


pilot and they will be recorded in future versions of this document. 


As of June 2, 2021, a formal plan to monitor the privacy requirements for the Lighthouse 


model has not been completed. 


Gap Analysis and Proposed Recommendations 


Retention and | No clear retention Meet with IM to determine a Not begun — 


Disposal and disposal retention and disposal schedule to engage 
schedules have been | for all Lighthouse data. with IM in 
determined. the coming 


weeks 
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Model Privacy Assessment 


Lighihouse ~ Study Permit Piot #2 


Version 1.0 Final ~ May 2021 


Monttoring A clear plan to Currently quality assurance Not begun 


monitor the mechanisms are in place to 
effectiveness of monitor the accuracy and 
privacy controls and | effectiveness of the model. 
adherence to privacy | However, Privacy recommends 
requirements. that a more detailed monitoring 
plan be developed to monitor 
adherence to privacy 
requirements or include it in 


existing documentation. 


Documents Reviewed to Gather Information 


The documents below are linked to their source in GCDOCS. As future readers of this 
MPA may not have access to those documents, below 1s a point-in-time capture of the 


documents as of May 20, 2021. Because they are point-in-time, note that they may be drafts, 


so please use the hyperlink when possible. 


1. Lighthouse Privacy Needs Assessment - 


hitp://ecdocs2/otcs/cs.exerfunc=&objaction=overview&objid=392470772 


A2SC - PNA - 
Lighthouse for SP.d: 


2. Lighthouse Project Charter - 
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Model Privacy Assessment 
Wigntnouse ~ Study Permit Pilot #2 


Version 1.0 Final ~ May 2021 


A2SC - Project 
Charter - Lighthouse 


3. Lighthouse Study Permit Pilot Legal Opinion - 


htt à: { gc coc 


s2/otes/cs.exe?func=ll&obiaction= overview& objid = 392337429 


Lighthouse Study 
Permit Pilot Legal O} 


Signature 


Tracy Perry 
ATIP Director 
Signed by: Perry, Tracy 
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Agreed. We will develop a few descriptive use-case stories/scenarios to make the usage transparent and clear, 
and include a process-flow diagram in the documentation to clarify the intended pilot use-case for the tool. In 
addition, we will add additional documentation defining the types of adverse information used by the system. 
Under the planned pilot, 7 | | E | a | | 


officer; the tool summarizes information from IRCC's database to help 
inform that decision. 
The report was written this way to keep it relevant to a lay audience, but we can make these changes. 


We will make adjustments to this wording to clarify where the system is predictive in nature. To clarify, the tool 
does not make recommendations and is not used directly in influencing administrative decision making on 
applications. It does not make recommendations or provide predictive scores, but rather summarizes factual 
information from ircc's data holdings on applications where a possible concern is identified. There is a 
predictive aspect in the sense that information is not shown on all applications, but rather only those that have 
some possible concern as identified in the data. 


As a demonstrative example: A simple univariate pattern example might be a case where the system presents 
the following information to a user: 


While an algorithm was used to identify that this information 
exists in IRCC's data holdings, the factual information presented is designed to stand entirely on its own merits as 
evidence to inform a decision about whether additional information should be collected from 


No trust or reliance is ever placed in the algorithm itself to drive a decision or present a 


recommendation, and decision making is solely based on factual information collected about the specific 


applicant, and is never influenced by extrapolation of facts from a past trend (i.e., prediction). This is the key 
point we are trying to highlight in differentiating the approach from a traditional binary classifier or predictive 


system. 


For added context, the current existing business at IRCC for verifying application information is roughly the same 
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This will be added to the report. Our general approach to bias/fairness is to ensure ongoing monitoring in the 
course of some relatively small low-risk piloting of the system (currently being considered for approval). Bias 
monitoring (primarily looking at distribution of false positive rates across demographic variables) is also built into 
the ongoing monitoring assessment. 


On the question of stereotypes, a major mitigation is the design of this pilot work, which will only use evidence 
from neutral non-subjective third-party sources of information. Toillustrate, the general use-case put forward is 
as follows: 

An applicant for a student permit raises a possible fraud concern by the system. A summary of the historical 
pattern is generated for a risk assessment officer, which shows that an application for a student permit shares 
similarities to a dozen other past applications that have used forged acceptance letters from "fakeSchoolName 
University" to try to enter Canada. The officer notices that this applicant also plans to study at fakeSchoolName 
and decides to verify with the school that this person is in fact enrolled there. They perform a verification by 
contacting the school to determine that the individual is enrolled. This response from the school will be 
assessed when deciding whether to approve or refuse the application. Of note, the officer that performs the 
verification and the officer that makes the decision on the application are different individuals. To avoid any 
fettering/biasing concerns, the officer making the decision does not see any output from the system and is not 
aware that it was used on this application. They have no knowledge of the 12 similar past applicants that 
committed fraud. As such, the decision is only influenced by factual "yes/no" evidence obtained from the 
school. As required, the decision is based solely on evidence specific to this exact applicant, and never on the 
basis of the 12 similar applicants who committed fraud in the past. 

This is the sole usage of the system considered for testing at present. We believe that this design effectively 
mitigates any concerns around bias or the perpetuation of stereotypes. Even if bias or stereotypes were present 
in the verifying officer, and this influences the decision to perform a verification, there is no room for this to 
influence the final decision on an application. 


This will be added to the report. The high-level plan is to regularly shift the time-window in which patterns are 
assessed, as well as to qualitatively assess the utility of the tool for risk assessment officers. This will ensure that 
the system is always displaying relevant and timely data and that stale information is not being presented. 
Future mitigations will be required to ensure that the system, once in production, does not self-reinforce on its 
past results. We have had some preliminary discussions about the possibility of using random sampling methods 
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This will be added to the report. 


Agreed. We are working with comms team on communications strategies. 


Agreed. Please see the point six above about the impact on clients of false positives (increased approval 
likelihood). We believe this would make some of the policing examples poor direct comparables, as these 
typically have significant negative impacts in the event of false positives. We will examine the research and draw 
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1. Provide an overview of the A2SC-developed Lighthouse (previously 
known as Watchtower) Risk Identification System. 


global Student Permit (SP) caseload. 
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Can be adapted to other IRCC business lines 


Can scan for many forms of data-detectable risk patterns, and can be configured for specific 
countries or risk types (e.g., misrep, organized crime, etc.) 


Enables RAUs and investigative teams to be more efficient and effective in identifying, 
validating and taking action on fraud and risk patterns 


Improves timeliness of verifications, thereby preventing delays in processing for a sma 
of files 


Cost avoidance from fewer adverse events (e.g., each asylum claim costs 
government roughly $16,000) 


Dovetails with existing intelligence-based risk detection approaches 


Modest costs for development and maintenance. Immediately deployable using exi 
infrastructure 
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System provide neutral, factual information to increase evidence available to officers 


e Lighthouse only provides information to support RAO decisions about when to 
collect additional evidence. 


¢ No decision automation. 


e All data used by the system originates from GCMS 


The pilot is designed to avoid fettering 


e Lighthouse information is only provided to risk assessment units for their 
consideration. 


e Adjudicating officers will not see Lighthouse risk patterns. 
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Engaged Stakeholders 

Integrity Risk Management (IRM) — Business Owner 
International Network (IN) 

Domestic Network (DN) 

Centralized Network (CN) 


Immigration Program Guidance (IPG) 


Legal Services (Department of Justice/LSU) 
Privacy (ATIP) 


Strategic Planning and Performance (SPP) 


immigration, Relugees immigration, Réfugiés 1 3 
and Citizenship Canada el Citoyenneté Canada 


A3745441_13-000200 


k Immigration, Refugees Immigration, Réfugiés 
and Citizenship Canada et Citoyenneté Canada 


Information disclosed under the Access to Information Act 


L'information divulquée en vertu de la loi sur l'accès à l'information 


2 


— 
M 


e A2SC goes to great lengths to ensure that Lighthouse is developed responsibly and does not 
introduce bias. 


e Steps include: 


1. 


2. 


3. 
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External review of Lighthouse by Statistics Canada 

Following best practices in data science to avoid bias and active monitoring of risk indicators 
Many layers of human review of the risk patterns to eliminate incremental bias 

Overall design centred on the interests of the client to avoid causing harm 

Active engagement with external stakeholders, including governance exercise in Winter 2020 


Follow the comprehensive ethics framework to govern AA work 
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AGENDA 


Basic Operation 


Data 
a) Overview 
b) Inputs 
c) Adverse Targets 


d) Contextual Information 


System Configuration 


ANNEX: System Design 


Immigration, Refugees Immigration, Réfugiés 
it de i and Citizenship Canada et Citoyenneté Canada 
Information disclosed under the Access to Information Act 
L'information divulquée en vertu de la loi sur l'accès à l'information 


A3745462_2-000298 


Pages 299 to / à 301 
are Withheld pursuant to sections 


sont retenues en vertu des articles 


s.16(1)(b), s.16(2)(c) 


of the Access to Information Act 


de la Loi sur l'acces a l'information 


Immigration, Refugees Immigration, Réfugiés 
it de i and Citizenship Canada et Citoyenneté Canada 
Information disclosed under the Access to Information Act 
L'information divulquée en vertu de la loi sur l'accès à l'information 


A3745462_6-000302 


Page 303 
is withheld pursuant to sections 


est retenue en vertu des articles 


16(1)(b), 16(2)(c) 


of the Access to Information Act 


de la Loi sur l'acces a l'information 


Immigration, Refugees Immigration, Réfugiés 
it de i and Citizenship Canada et Citoyenneté Canada 
Information disclosed under the Access to Information Act 
L'information divulquée en vertu de la loi sur l'accès à l'information 


A3745462_8-000304 


Pages 305 to / à 307 
are Withheld pursuant to sections 


sont retenues en vertu des articles 


s.16(1)(b), s.16(2)(c) 


of the Access to Information Act 


de la Loi sur l'acces a l'information 


Immigration, Refugees Immigration, Réfugiés 
it de i and Citizenship Canada et Citoyenneté Canada 
Information disclosed under the Access to Information Act 
L'information divulquée en vertu de la loi sur l'accès à l'information 


Key Question for Project Team 


A3745462_12-000308 


Pages 309 to / à 323 
are Withheld pursuant to sections 


sont retenues en vertu des articles 


s.16(1)(b), s.16(2)(c) 


of the Access to Information Act 


de la Loi sur l'acces a l'information 


Page 324 
is withheld pursuant to sections 


est retenue en vertu des articles 


16(1)(b), 16(2)(c) 


of the Access to Information Act 


de la Loi sur l'acces a l'information 


Page 325 
is withheld pursuant to sections 


est retenue en vertu des articles 


16(1)(b), 16(2)(c) 


of the Access to Information Act 


de la Loi sur l'acces a l'information 


Page 326 
is withheld pursuant to sections 


est retenue en vertu des articles 


16(1)(b), 16(2)(c) 


of the Access to Information Act 


de la Loi sur l'acces a l'information 


Pages 327 to / à 329 
are Withheld pursuant to sections 


sont retenues en vertu des articles 


s.16(1)(b), s.16(2)(c) 


of the Access to Information Act 


de la Loi sur l'acces a l'information 


Page 330 
is withheld pursuant to sections 


est retenue en vertu des articles 


16(1)(b), 16(2)(c) 


of the Access to Information Act 


de la Loi sur l'acces a l'information 


Pages 331 to / à 332 
are Withheld pursuant to sections 


sont retenues en vertu des articles 


s.16(1)(b), s.16(2)(c) 


of the Access to Information Act 


de la Loi sur l'acces a l'information 


Page 333 
is withheld pursuant to sections 


est retenue en vertu des articles 


16(1)(b), 16(2)(c) 


of the Access to Information Act 


de la Loi sur l'acces a l'information 


k Immigration, Refugees Immigration, Réfugiés 
and Citizenship Canada et Citoyenneté Canada 


Information disclosed under the Access to Information Act 


L'information divulquée en vertu de la loi sur l'accès à l'information 


Meeting Instructions 


please post any questions, comments or considerations using the chat function in MS Teams 
as they arise during this meeting. These questions and comments will not be addressed directly in this session, but will 
be collected at the end of the meeting and used to frame subsequent project team discussions that will explore these 
issues in depth. 


1) introduce themselves 
2) Identify their team’s mandate as it relates to watchtower and 
3) list one thing they would like to see achieved by the end of this project. 
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Project Goals 


- Engage Key IRCC Stakeholders for deeper involvement and understanding on watchtower. 
- Design, Draft and Test draft usage and governance processes for the tool. 
- Lay key groundwork to support continued development of the tool at IRCC. 


IN SCOPE 

- Usage and governance 

- Legal and privacy considerations 
- Risk Identification/Mitigation 


OUT OF SCOPE 
- Technical design / development (user interface, etc.), with possible rare exceptions 
- Areas covered by existing governance or operating procedures for risk assessment. 
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Artefacts 


Governance Framework 
e Authorities, approvals, key decision-points, etc. 


Usage Processes 
e Documentation, officer instructions, retention, etc. 


Legal & Privacy Opinions 
e Possible updates to existing documents/drafts. 


Project Risk Assessment / Mitigation Plan 


Considerations Report 
e “Parking Lot” for issues outside the scope of this project 


Project Report 


Immigration, Refugees Immigration, Réfugiés 
it de i and Citizenship Canada et Citoyenneté Canada 
Information disclosed under the Access to Information Act 
L'information divulquée en vertu de la loi sur l'accès à l'information 


A3745466_4-000337 


Immigration, Refugees Immigration, Réfugiés 
it de i and Citizenship Canada et Citoyenneté Canada 
Information disclosed under the Access to Information Act 
L'information divulquée en vertu de la loi sur l'accès à l'information 


Project Structure 


Up to 12 weeks in length 


Weekly project team meetings (1-hour) 


Meetings will be a mix of: 
e structure d o ramnstorrm ng sessions 


assions; and 


e “in the weeds” « g 
e presentations/demos 


A2SC to act as convenor/facilitator 


Project Team: OPPB (A2SC), IRM, IPG, CN, DN, IN, Legal, Privacy, SPP, CMB, Admissibility 
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RoundTable 


1) Introduce yourself (and any others participating from your team) 
2) Identify your team’s mandate as it relates to watchtower 


3) One thing you would like to see achieved through this project 


A2SC, IRM, IPG, CN, DN, IN, Legal, Privacy, SPP, CMB, Admissibility 
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This document serves as a tool for the Department to assess the privacy needs for your initiative, document 
your program area's commitment to taking appropriate steps to protect privacy in your initiative, and to 
prioritize it in IRCC’s privacy work plan. Based on this assessment, we may determine that no privacy work 
is required, or we may recommend: 


e the development of a new Privacy Impact Assessment (PIA); 
e anamendment or update to one or more existing PIAs or 
e other privacy work, as appropriate. 


It is essential that you provide accurate and complete information so that we can provide the most 
appropriate recommendations and optimal support. 


Steps to complete the PNA Document 


=” fo , 


* Complete Part 3 : 


Insert initiative + Complete Part 4 - 


Chief Privacy 


-~ nameonpagel : _ «Notify Program | - Sign Part 5 

e Complete Parts | (Program Lead Officer ** 
1&2 | Director) | + Notify Program 
| + Notify ATIP * | Notify ATIP * | 


ee erent AMAIA HATES TEI eect a a AAO EEE EELS ES EEL ESE ELSES EEC, 


* Send the document to the AFF Division. 


** In cases where Privacy Compliance Evaluation (PCE) is being sought, you must obtain the signature of ADM 
Corporate Services Sector 


The information provided tn this section will be used to: 


e better understand your initiative and how it aligns with departmental priorities; and 
e prioritize our review and support of your initiative in a manner commensurate with its complexity 


and risk. 
x X X ie i EU 
= ; : aa a a A RAR Sere ee ees 
Initiative Business Ownet 
SRE AL Ue LA RS PRE Oo ut VN EERE 


Sector/6 Di IN, CN and DN 


Director Ellie Weber (CN) 


Program area contact Joshua Parkinson (CN) 
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Descriptio 


Describe your initiative: 


e What is the purpose? How will the initiative operate? 
e How will the personal information be used? Specify whether personal information is being used to 


make decisions that directly affects individuals. 
e Is this a new program or a modification to an existing one? 
o If itis a modification to an existing program, select from the options below, and be sure to 
describe both the existing program AND the proposed modifications 


Does the initiative involve any of the following changes to current methods for handling personal 
information? 


a ae 

or disclosure to electronic systematic disclosure 

a 
partners population technologies 

a | 
indirect collection surveillance 


ge 


Alignment with IRCC’s Departmental Results Framework 
Identify all program activities in which the initiative is incorporated. If the information cannot be provided, 
only check the “Unsure” option at the bottom of the table below. 
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Immigrant and Refugee Internal 
Selection and Integration Services 


Federal Economic Acquisition Services 
Immigration Communications Services 


Provincial Economic Financial Management Services 


Immigration 
g Human Resources Management 


Family Reunification Services 


Humanitarian / 
Compassionate & 
Discretionary Immigration 


Information Management Services 
Information Technology Services 


Legal Services 
Refugee Resettlement 


Management & Oversight Services 
Asylum 


Material Services 
Settlement 


Real Property Services 


Travel & Other Administrative 
Services 


x 3 à z: e i : Fo i é 5 Pa a $ 3 = = i my z n x. a 

x gE EEE T E ROSES T T ga Ba à Se MR kone = is oo sau 2 Ua SD ts a PRE RE Ng Rg ae 
fA PPE PR PPA ER PNY VAP YT PR MSR ETP PAF 4 i eS er OO ae Seam as ber gn ai Se ee Re ea 
SAP RSP Oe op oe Ss BSE Ae oops bed = ROSES F $ s RoR SES À PE IE BE aT 3 = SS Ss oe a ty 
PORES ey! Pl PPM PPR MW PR Po AA ke Re PF ees B : <P PR RRP AR PY PRA a Pb Pe PO PR A RS 


Indicate if the initiative is linked to one or more sector, departmental or government of Canada priorities. 


U No M Yes ~ Describe the priority and provide links 


"Manage increased temporary resident volumes while advancing transformation”, ‘ACC 2018-2021 
integrated Plan, p. 5 


E3 SA š š ; x 
$ F ; i : ; 
Fa cone ne ae a ga Le. te ee sae = a a = a “ n 3 ee wt mi ~ 
FCO ea RAR Re Ra Re Poa Ge EGA GAA es ae ae 
PUPPY, SS bi Paes Pray PP PiPaisa FY sari yA Pie ar 
i PPA ee PAS PP PEELS EMP SPRL PRA LP Ae Pd 


Provide the timeline for the initiative. Specify the start and end dates. If there is no end date, please specify 
whether the initiative is permanent, has no end date or the end date Is unknown. 


Pilot will run for a limited time: 


M This initiative is a pilot project 


COVID-19 Impact 
Specify if the initiative is related to COVID-19. The Privacy Compliance Evaluation (PCE) is a streamlined way 
of conducting a privacy analysis for urgent COVID-related initiatives in lieu of a full PIA. 


E No L] Yes (Provide a brief explanation below) 
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CT This COVID-related initiative continues beyond March 31, 2021. 


If not, indicate the end date below. 


¢ a x 
i $ ou 
CANNES CNRS RENE CORRE ES Ant RAR RAR ge 
Pm ERE UR YT EAP be PEAS TR AY PRY es fe 
CAE SRE ahah SSS SPO a Se Sah $ 
PAU A A RAPIE O, ORR OO RR RS à 

ÿ 


To your knowledge, are there are any PIAs (completed or ongoing) related to this initiative or activity? If 
you are aware of PIAs related to similar initiatives at other federal departments, please include them as well. 


y ë A A 

X À. Ps 

eg Ra pe ARR GRRE RGR ARS RSG AR 

PYAR Te PT AACS cho co PP ek PATS 
5 a oat Roe ROP Loin 


CT Unknown [| No M Yes 


If yes, indicate below the titles of the other PIAs related to this one by specifying for each whether it is completed or 
still ongoing. 


A2SC completed a PIA for its use of advanced analytics in support of TRVs from China and India 
“Privacy Impact Assessment: Use of Advanced Analytics in IRCC Programs”). The work proposed here Is 
ery closely related 


i ae g 
$. oo De Re Bg 
Saat 


The Privacy Act requires institutions to ensure there is parliamentary authority for the program or activity 
for which the personal information is collected, used and disclosed. Such authority is usually contained in: 


e an Act of Parliament or subsequent Regulations; 

e an approval of expenditures proposed in the Estimates and as authorized by an appropriation Act 
or; 

e activities conducted as part of the administration of the program. 


Identify the relevant authorities in the table below. We have included common legislative authorities at IRCC 
as examples. 


Note: The Privacy Act is not a legislative authority for the collection or creation of personal information. 
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* For internal service programs that draw authority from the Financial Administration Act, you must also specify which 
policies apply to the programs. Government of Canada policies can be found at: httos://www.tbos-sct.gc.ca/pol/index- 


enc ASAK 


Does this initiative require new legislation or an amendment to an existing piece of legislation? 


Mm No L] Unknown L] Yes (Please describe below) 


= : PERR į on 
i ee eS $ FENTE A 
TS gee gare ORR aw gee RS 
inormation Bank FI) 
3 LS PORC AUS A PP OP EAU HAN ON ee 
+ $ 


ccentiying a Persona PIB 
What is the Personal information Bank (PIB) for your program or activity? Please select one of the options: 


CT Unknown 
L] A new PIB will need to be developed 


M There is an existing PIB. Please list the name and number below. 


Two PIBs were updated to include computer analytics: 


e Migration Control and Security Management (PPU 068) 
e International Students (PPU 051) 


ges CE Mood oo $ 5 wre 2 FR 

7 S. à 5 Fa = y š pot gost x è 

Fi EAA A BA RAR RAR aa ROSE OSEAN PALS Ge Sige E E RES RAL ONG Sa RR Sapa Sa SR = 
Mh PEA PY. Ee Pe Po PAP RF SR PS PPPS EP PAP PAP YS AP iP a Py d PSa $ 

e A E E A Lun Rb À UN AA A Pb di Lei db ie LAA iy LAL So 


From the non-exhaustive listing of possible data elements below, indicate all applicable data elements 
collected or created in the initiative by checking the box attached. 


M Not Applicable (no new collection of personal information) 


Physical attributes - _ Biometric information (photo, fingerprint, etc.) 


. Opinions or views 


If necessary, add below any other applicable data elements. 
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Other than the employees within the program area responsible for the initiative, indicate all partners 
involved in the handling of personal information/data throughout the life of this initiative and the nature of 
their involvement, whether fully or partially. 


This includes other IRCC branches/divisions, other federal departments, municipal, provincial/territorial governments, 
foreign governments, foreign organizations, private organizations, etc. 


LI Not Applicable 


Retention 


O x |X| Analysis 
pd | Governance 


Provide a brief description of how each responsibility is fulfilled: Identify MOUs or other similar instruments that 
currently govern the sharing or are under negotiation. 


IRM is currently drafting a governance and risk mitigation framework for Watchtower. 


Statutory Prohibitions 


_ Chat bots | _ Active or passive surveillance, monitoring or 
: - _ investigation 


Artificial intelligence 


If you check any of the above boxes, elaborate below. 
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x Fo 
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Is it anticipated that the public or departmental employees will have any privacy concerns regarding the 
proposed program or service? 


L] Yes (Please describe below) CL] No Mm Unknown 


Clarification is required before a recommendation can be made L] Yes CI No 
A new or modified PIA is required L] Yes LI No 
A new or modified privacy protocol is required L] Yes CI No 
Limited privacy work is required L] Yes LI No 
No privacy work is required at this time L] Yes LI No 


[] We concur with the assessment and will follow the ATIP Division's recommendations. 
-OR- 
C] We do not concur with the assessment and will not follow the ATIP Division's recommendations. 


Describe what actions you will take instead of the ATIP Division recommendations. 


-OR- 
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In cases where a PIA is required, but the initiative is COVID-related and the urgency will prevent the 
department from submitting a PIA prior to implementation, the Treasury Board of Canada Secretariat (TBS) 
has issued an Interim Directive on Privacy Impact Assessment to address the challenges initiatives might 
deal with while complying with privacy law and rules. This Interim Directive (section 6.4) allows, in 
exceptional circumstances, the completion of a Privacy Compliance Evaluation (PCE) in lieu of a full PIA, 
as a streamlined way of conducting a privacy analysis for urgent COVID-related initiatives. 


For COVID-related initiatives that end by March 31, 2021: 
[] Because of the urgency of the initiative, we are seeking approval from the ADM Corporate Services Sector to 
complete a PCE (in lieu of a PIA) prior to implementation. 


For COVID-related initiatives that continue past March 31, 2021: 

LI Because of the urgency of the initiative, we are seeking approval from the ADM Corporate Services Sector to 
complete a PCE (in lieu of a PIA) prior to implementation. We commit to completing a PIA before September 30, 2021, 
in addition to the PCE. 


Justification for the PCE 
Explain the urgency of the initiative and demonstrate why a PIA cannot be completed prior to 
implementation. 


Signature instructions 


(1) Right-click on the signature block & select the option “Signature Setup...” 

(2) Goto “Suggested signer”: replace the current content with the complete name of the Program Director 

(3) Go to “Suggested signer’s title”: replace “[Division Name]” with the official name of your 
Division 

(4) Click on “OK” 

(5) Right-click on the signature block & select the option “Sign” 


X 


[Program Lead Name] 
Program Lead Director, [Division Name] 
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X 


Simon Cardinal 
Chief Privacy Officer 


For Covic-related Initiatives 
| authorize the program area to complete a PCE in lieu of a PIA (as identified in Part 4). 


L] Yes CT No 


X 


Holly Flowers Code 
A/ADM, Corporate Services 
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Feb 4, 2021 Adjustments based on feedback on 
first draft from IRM, Legal Services 
and Privacy 


4.0 Mike Haymes Aug 15, 2071 Updated for the new pilot working 
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Project Approval 


This project was approved for deployment on June 25, 2021, by the Director General of OPPB. This 
approval followed briefings on the project with the ADM, Operations, and presentation to the Data 
Executive Steering Committee (DESC) on June 1, 2021. The pilot was also endorsed by the Integrated 
Network Steering Committee (INSC) meeting on May 13, 2021. 
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